Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 138 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| bc3bc6e8-aae7-451e-b26a-cc5e8fcd0a33 | < 2.3.10 |
HIGH | 8.8 | The WP Google Map plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature. | — | wordfence |
| bc17284e-65ea-4e67-aba9-3475f0174657 | HIGH | 8.8 | The Post Saint: ChatGPT, GPT4, DALL-E, Stable Diffusion, Pexels, Dezgo AI Text & Image Generator plugin for WordPress is… | — | wordfence | |
| bc0983d7-6c7e-41cb-8997-578d362d9c9f | < 3.6.4 |
HIGH | 8.8 | Multiple FunnelKit plugins are vulnerable to Sensitive Information Exposure via the wf_get_cookie shortcode. This makes … | — | wordfence |
| bbf9a765-3718-4957-aa18-562654824fbf | < 1.5.8 |
HIGH | 8.8 | The Countdown and CountUp, WooCommerce Sales Timers WordPress plugin is vulnerable to Cross-Site Request Forgery via the… | — | wordfence |
| bbd8dc5f-7a62-4258-a13e-e5cec911fdc4 | < 3.0.0 |
HIGH | 8.8 | The Events Calendar for Google plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc… | — | wordfence |
| bbc91abd-d865-45a2-bc37-f34cb10f1863 | < 3.1.3 |
HIGH | 8.8 | The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/edit.php CSRF with resultant XSS. | — | wordfence |
| bbc00c4b-c360-4614-b9bc-30d899b812f1 | < 1.9.5 |
HIGH | 8.8 | The WP Last Modified Info plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includi… | — | wordfence |
| bbae9c33-becb-4c9d-917f-0d8fe8312d0c | < 2.37 |
HIGH | 8.8 | The Advanced Woo Labels plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including… | — | wordfence |
| bb65d916-7d9e-4562-ab9b-c7ba012a08fb | < 1.3.5 |
HIGH | 8.8 | The Accessibility by AllAccessible plugin for WordPress is vulnerable to unauthorized modification of data that can lead… | — | wordfence |
| bb5e6767-d0a9-4ac4-816f-6fb57b1e5f9b | < 2.8.9 |
HIGH | 8.8 | The Uncode Core plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.8.8. This… | — | wordfence |
| bb3be09d-6f65-48cc-b692-f4231d3f6858 | HIGH | 8.8 | The SermonAudio Widgets plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.9.3 due … | — | wordfence | |
| bb3aa613-8f34-4d96-8ddf-41fcdcf65c59 | < 12.3.20 |
HIGH | 8.8 | The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the βurlβ param… | — | wordfence |
| bb267bbd-cd62-49f7-9abc-c6734b23be22 | < 1.9.13 |
HIGH | 8.8 | The Tumult Hype Animations plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type va… | — | wordfence |
| bb0e77e1-7e9f-4f7e-8953-c86ab0e5ae7a | < 6.8 |
HIGH | 8.8 | The Simple User Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including… | — | wordfence |
| bae06fa8-546c-4daf-8335-a5e24f6704d4 | HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in the Stream Video Player plugin 1.4.1 for WordPress allows remote atta… | — | wordfence | |
| bac57319-3b0c-4b83-af9e-7b5539ef087a | < 2.4 |
HIGH | 8.8 | The wsecure plugin before 2.4 for WordPress has remote code execution via shell metacharacters in the wsecure-config.php… | — | wordfence |
| bab07bc7-d428-4ef9-91e8-4203fc8a32dd | < 1.6.6 |
HIGH | 8.8 | The RTMKit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versi… | — | wordfence |
| ba79bf95-08f8-4aa6-968b-f76a09ce52b8 | < 4.2.6.9 |
HIGH | 8.8 | The LearnPress β WordPress LMS Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to… | — | wordfence |
| ba317acb-d45c-42c0-b5fb-b163bcd59340 | < 1.7.1 |
HIGH | 8.8 | The Contact Form to DB by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the cntctfrmtdb_department… | — | wordfence |
| ba0a1b59-90c2-4bdd-9594-5866df96cfb8 | HIGH | 8.8 | The Wovax IDX plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and… | — | wordfence | |
| b9f99b51-e1b1-4cd3-a9f7-24e4b59811a7 | < 1.14.6 |
HIGH | 8.8 | The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 … | — | wordfence |
| b9ead8f1-f2d7-4087-bb6c-de15bf8318a3 | < 1.2.9 |
HIGH | 8.8 | Metronet Tag Manager version 1.2.7 contains a Cross site Request Forgery (CSRF) vulnerability in Settings page /wp-admin… | — | wordfence |
| b9e499c4-e683-4587-b0ab-7f4ecde94e41 | < 2.7.7 |
HIGH | 8.8 | The Video Share VOD β Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Cross-Site Request Forge… | — | wordfence |
| b994f9ee-b59b-4bcd-9057-4cfbb5f22694 | HIGH | 8.8 | The Wayne Audio Player plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… | — | wordfence | |
| b97d2b63-7eaa-4518-b838-35d4b993743d | < 1.20.1 |
HIGH | 8.8 | The Orderable β WordPress Restaurant Online Ordering System and Food Ordering Plugin plugin for WordPress is vulnerabl… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →